top of page

CMMC Compliance in 2026: A Current Guide for Defense Contractors and Suppliers | My ISO Consultants

Writer: My ISO Jay
My ISO Jay
Apr 15
6 min read

Updated: Sep 18

CMMC compliance is still a critical issue for defense contractors and suppliers in 2026, but the compliance timeline has changed. The planned Phase 2 rollout was suspended in July 2026, and the CMMC program remains paused in Phase 1 while the Department reviews the program.


That pause does not eliminate existing cybersecurity obligations. Contractors and subcontractors that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) still need to understand the requirements in their contracts, maintain required safeguards, complete applicable self-assessments and affirmations, and support their compliance statements with evidence.


Current CMMC Status in 2026

The original CMMC rollout schedule called for Phase 1 to end in November 2026 and Phase 2 to begin on November 10, 2026. That schedule is no longer current. Phase 2 requirements were suspended, and Phase 1 self-assessment requirements remain in place.


Defense contractors should therefore avoid planning around a fixed November 2026 certification deadline. The more important question is what requirements apply to the organization's current contracts and whether the company can demonstrate compliance with them today.


For a focused explanation of the suspension and why NIST SP 800-171 still matters, see CMMC Phase 2 is Paused: Why NIST SP 800-171 Compliance Still Matters for Defense Contractors.


Who Needs to Pay Attention to CMMC?

CMMC requirements are tied to the type of federal information an organization handles and the requirements incorporated into its solicitations, contracts, or subcontracts.


Level 1: Federal Contract Information

Organizations that handle Federal Contract Information may be subject to CMMC Level 1 requirements. Level 1 focuses on the 15 safeguarding requirements in FAR 52.204-21 and currently requires an annual self-assessment and annual affirmation when the requirement applies.


Level 2: Controlled Unclassified Information

Organizations that process, store, or transmit Controlled Unclassified Information may be subject to Level 2 requirements. Under the current Phase 1 framework, Level 2 self-assessment is based on the 110 security requirements in NIST SP 800-171 Revision 2, with a self-assessment every three years and an annual affirmation of continued compliance.


Results are entered into the Supplier Performance Risk System (SPRS) when required. The general Phase 2 rollout of Level 2 third-party certification assessments has been suspended, but contractors should continue reviewing each solicitation and contract for current cybersecurity requirements.


CUI, FCI, and ITAR Are Not the Same Thing

One of the most common compliance mistakes is treating CUI, FCI, and ITAR as interchangeable. They can overlap, but they are not the same regulatory concept.


  • FCI is federal contract information that is not intended for public release and is protected through basic safeguarding requirements.

  • CUI is government information that requires safeguarding or dissemination controls under applicable law, regulation, or government-wide policy.

  • ITAR regulates certain defense articles, services, and technical data. ITAR applicability does not automatically determine a CMMC level.


A contractor should determine CMMC applicability from the contract, the information being handled, applicable DFARS or FAR clauses, and official program requirements rather than assuming that any defense-related technical information automatically creates the same compliance obligation.


Which Version of NIST SP 800-171 Applies?

NIST has published Revision 3 of SP 800-171, but the current CMMC program continues to use NIST SP 800-171 Revision 2 for Level 2 assessments. The Department has stated that Revision 3 will be incorporated through future rulemaking.


Until that transition is formally implemented, contractors should not assume that a newer NIST publication automatically changes the contractual assessment baseline. The applicable requirement should be verified against the contract and current official guidance.



Current Self-Assessment and Affirmation Requirements


Level 1

  • Annual self-assessment.

  • Annual affirmation of compliance.

  • Assessment results entered into SPRS when required.

  • POA&Ms are not permitted for Level 1.


Level 2 Self-Assessment

  • Self-assessment every three years.

  • Annual affirmation of continued compliance.

  • Assessment results entered into SPRS.

  • Limited use of a Plan of Action and Milestones (POA&M) is permitted under current program rules.

  • Permitted POA&M items must be closed within the required 180-day period.


Organizations should avoid treating the self-assessment as a paperwork exercise. Scores and affirmations should be supported by actual implementation evidence, current documentation, and a defensible understanding of the systems that handle protected information.



What Defense Contractors Should Have in Place


  • A clearly defined system boundary for environments that process, store, or transmit FCI or CUI.

  • A current System Security Plan (SSP) that accurately describes the environment and implemented security requirements.

  • Policies and procedures that reflect actual operations.

  • Technical evidence showing that required controls are implemented.

  • Accurate SPRS assessment information where applicable.

  • Documented responsibility for maintaining cybersecurity controls and compliance evidence.

  • Permitted POA&Ms that are actively managed and closed within required timeframes.

  • A process for reassessing the environment when systems, locations, vendors, or contract requirements change.


Subcontractors and Suppliers Cannot Ignore CMMC

CMMC is not only a prime-contractor issue. Cybersecurity requirements can flow down through the defense supply chain when subcontractors or suppliers receive covered information.


The required CMMC level is not necessarily identical for every company in the chain. The applicable requirement depends on the information being shared and the contractual terms. Prime contractors and subcontractors should understand what information is being flowed down, what security requirements accompany it, and what evidence is required to demonstrate compliance.


What About C3PAO Certification?

The general Phase 2 rollout of Level 2 third-party certification assessments has been suspended. That means defense contractors should not assume that the previous November 2026 schedule still determines when a C3PAO certification will be required.


However, companies should not abandon certification readiness. A strong NIST SP 800-171 implementation, accurate documentation, defensible self-assessment, and organized evidence will make future certification or government assessment requirements easier to address when the program is updated.


Compliance Tools Can Help, but They Do Not Create Compliance

Governance, Risk, and Compliance (GRC) platforms and structured tracking tools can help organize requirements, evidence, responsibilities, and remediation work. They can be useful for larger or more complex environments, but no specific software platform is required simply because an organization is pursuing CMMC compliance.


The tool should support the compliance program, not replace the underlying technical controls, policies, evidence, and management accountability.



A Practical CMMC Readiness Roadmap


  • Review current and upcoming contract requirements.

  • Determine whether the organization handles FCI, CUI, or both.

  • Define the systems and assets that fall within the compliance scope.

  • Perform a structured gap assessment against the applicable requirements.

  • Update the SSP and supporting policies so they accurately reflect the environment.

  • Remediate missing or ineffective security requirements.

  • Collect objective evidence that controls are operating as intended.

  • Complete required self-assessments and submit accurate information to SPRS.

  • Maintain annual affirmations and ongoing compliance activities.

  • Monitor official CMMC reform announcements and contract changes.


Organizations that need help evaluating their current readiness can use My ISO Consultants' CMMC and NIST SP 800-171 consulting services for gap analysis, documentation support, control implementation guidance, internal readiness reviews, and assessment preparation.


Why Accurate Cybersecurity Representations Matter

Defense contractors should take self-assessment scores, affirmations, and other cybersecurity representations seriously. Recent federal enforcement actions have continued to focus on contractors and suppliers that allegedly failed to meet contractual cybersecurity requirements or submitted inaccurate information about their compliance.


The safest approach is to make sure every score, affirmation, and compliance statement can be supported by current evidence and an accurate understanding of the systems covered by the contract.


Frequently Asked Questions


Is there still a CMMC deadline in November 2026?

No fixed November 2026 Phase 2 deadline should be relied on today. The planned Phase 2 rollout was suspended in July 2026, and the program remains paused in Phase 1 while it is reviewed.


Do defense contractors still need to comply with NIST SP 800-171?

Yes, when NIST SP 800-171 requirements apply through the contract. The current CMMC Phase 1 framework continues to use Revision 2 for Level 2 self-assessments.


Does every defense contractor need CMMC Level 2?

No. The required level depends on the information the organization handles and the requirements included in the solicitation, contract, or subcontract. Level 1 generally relates to FCI, while Level 2 addresses CUI.


Does ITAR automatically mean we need CMMC Level 2?

No. ITAR and CMMC are separate compliance frameworks. They can overlap in defense environments, but CMMC applicability should be determined from the contract and whether FCI or CUI is involved.


Should we wait for CMMC reform before working on compliance?

No. If cybersecurity requirements already apply through your contracts, the obligation exists now. Improving current controls, documentation, evidence, and self-assessment accuracy will also put the organization in a stronger position when the CMMC program moves forward again.


Conclusion

CMMC compliance in 2026 is no longer about racing toward a November Phase 2 deadline. It is about understanding current contract requirements, protecting FCI and CUI, maintaining defensible self-assessments and affirmations, and being prepared for future program changes.


If your organization needs help determining what applies and what needs to be fixed first, My ISO Consultants provides CMMC and NIST SP 800-171 consulting services to help defense contractors and suppliers identify gaps, strengthen implementation, and prepare for current and future assessment requirements.



Deadline
CMMC Deadline November 9th of 2026

(844) MYISOPRO

PO Box 4372

Crestline, CA 92325

We service the entire United States and most countries, but we consider the following areas of California, Arizona, Texas and Nevada "Local" to us: San Bernardino County, Riverside County, Los Angeles County, Orange County, San Diego County, Ventura County, Sacramento County, San Jose, Santa Clara County, Fresno County, Phoenix Area, San Antonio, Austin, Reno and Las Vegas areas

© 2025 by My ISO Consultants

bottom of page